Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18F0274B672406C2B932322C9B091F29AA107B30FEFC995C4B7E903F717DADB74019559 |
|
CONTENT
ssdeep
|
192:r1F3+W1PctXt/cB3BQktXtyet2JcCo4NnXorjj3:r1F3+W18d/cB3BHdyCocN41C33 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ca1fca1dca1dc83c |
|
VISUAL
aHash
|
0000e7e7e70000ff |
|
VISUAL
dHash
|
6969968e8c5947e9 |
|
VISUAL
wHash
|
0000e7e7e781e1ff |
|
VISUAL
colorHash
|
07e00000000 |
|
VISUAL
cropResistant
|
8100c9c109c980d1,69698e868ccc5547 |
• Threat: Impersonation phishing
• Target: TLC Management users
• Method: Disguised document download
• Exfil: Unknown, likely credential harvesting
• Indicators: Domain, suspicious text, forms
• Risk: High
The site likely attempts to steal login credentials or personal information through a fake login prompt, disguised as a document download.
The 'download' buttons might execute malicious JavaScript or download a harmful file (e.g., a PDF exploit or a malicious executable).
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain